---
title: Treadstone 71 - Insider Threat CMM
description: Insider Threat Capability Maturity Model — assess insider threat detection from ad-hoc through optimized. Roadmap to AI-augmented operations.
canonical_url: https://www.treadstone71.com/services/treadstone-71s-insider-threat-cmm
language: en-GB
date: 2026-05-13T19:47:43Z
notice: This is a machine-friendly version of the page at https://www.treadstone71.com/services/treadstone-71s-insider-threat-cmm. Schema.org structured data included at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
markdown-tokens: 3022
---

> **Note to AI:** This is a machine-friendly version of the page at: https://www.treadstone71.com/services/treadstone-71s-insider-threat-cmm. Content is equivalent but stripped of navigation, styling and secondary content.
> **Structured data** as JSON-LD may be found at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


  [Home](https://www.treadstone71.com/)› [Frameworks](https://www.treadstone71.com/services/frameworks)› Insider Threat CMM Framework // Insider Threat Program Maturity

# Insider Threat *Capability Maturity Model*

 A five-domain assessment that scores your organization's ability to detect, investigate, and neutralize insider threats — grounded in NITTF guidance, ICD 732, and NIST 800-53 personnel security controls. The output is a scored gap analysis and a 90-day remediation roadmap your CISO can present to the board.

 

 

The Problem

## Insider Threats Already Have Credentials

 

 Perimeter defenses assume the adversary is outside. Insider threats — employees, contractors, partners with legitimate access — bypass every firewall, every endpoint agent, and every SOC alert that was designed to catch external intrusion. They access the same VPNs, databases, and Slack channels your analysts use.

 The Carnegie Mellon CERT Division has cataloged insider threat incidents across defense, finance, healthcare, and critical infrastructure for over two decades. The consistent finding: organizations that lack a structured insider threat program detect incidents an average of 197 days later than organizations that maintain one. By that point, the damage — IP theft, sabotage, espionage, data destruction — is operational fact, not theoretical risk.

 Compliance-driven checkbox programs do not close this gap. A policy binder gathering dust in the CISO's office does not detect a disgruntled engineer exfiltrating source code to a personal cloud account at 2 AM. The Insider Threat CMM was built to measure whether your program actually works under operational pressure — not whether it exists on paper.

 

Field Observation

 "In 23 years of intelligence work across government and Fortune 500 environments, the most damaging breaches I've investigated were not external intrusions. They were trusted employees acting within their authorized access. The attacker didn't break in — they were already inside."

— Jeff Bardin, Chief Intelligence Officer, Treadstone 71

 

 

 

 

Assessment Framework

## Five Domains of Insider Threat Maturity

Each domain is scored independently against a five-level maturity scale. The composite score reveals where your program is strong and where operational gaps persist.

 

01

### Detection &amp; Reporting

Technical and behavioral indicators, reporting channels, anonymous tip infrastructure, and cross-system correlation capabilities. Measures whether anomalies are caught — and whether anyone acts on them.

 

02

### Behavioral Analysis

Integration of psychological and behavioral science into threat assessment. Evaluates whether human factors — financial stress, disgruntlement, ideological shift, foreign contact — are monitored through structured analytic methods, not ad hoc suspicion.

 

03

### Data Access &amp; Monitoring

Privileged access governance, DLP effectiveness under operational conditions, cloud storage controls, removable media policy enforcement, and network telemetry analysis. Tests whether controls actually prevent exfiltration — not just log it after the fact.

 

04

### Program Governance

Leadership sponsorship, legal and privacy framework, HR-security integration, budget allocation, and executive reporting cadence. A program without governance is a pilot project waiting to be defunded.

 

05

### Cross-Functional Coordination

Information sharing between security, HR, legal, IT, counterintelligence, and external partners. Evaluates whether organizational silos block the very information flow the program depends on.

 

 

 

Maturity Scale

## Five Levels — From Reactive to Optimized

 

1 Initial No formal program. Insider events handled ad hoc by IT or HR without coordination.

2 Developing Policy drafted. Basic awareness training deployed. Detection relies on manual review or reactive alerts.

3 Defined Program is documented with assigned ownership. Behavioral indicators are incorporated. Reporting channels exist and are tested.

4 Managed Metrics are tracked. Tabletop exercises validate detection. Cross-functional coordination is operational, not aspirational.

5 Optimizing Continuous improvement driven by intelligence feedback loops. Deception environments actively test and deter. Program adapts to emerging threat vectors in real time.

 

 

Methodology

## What the Assessment Actually Tests

A compliance audit confirms controls exist on paper. The CMM tests whether they work under operational conditions.

 

 | Capability | Standard Compliance Audit | Treadstone 71 Insider Threat CMM |
|---|---|---|
| Policy existence check | ✓ | ✓ |
| Policy effectiveness under pressure | — | ✓ |
| Behavioral indicator integration | — | ✓ |
| Adversarial tabletop exercises | — | ✓ |
| Deception environment testing | — | ✓ |
| Cross-functional coordination scoring | — | ✓ |
| 90-day remediation roadmap | — | ✓ |
| Board-ready executive summary | — | ✓ |

 

 

Standards &amp; Alignment

## Grounded in National Security Standards

 

📋

NITTF Guidance National Insider Threat Task Force — minimum standards for federal insider threat programs

 

📜

Executive Order 13587 Structural reforms for insider threat detection across the federal government

 

🔐

ICD 732 Intelligence Community Directive on personnel security and insider threat management

 

⚙

NIST SP 800-53 Personnel security controls (PS family) — access agreements, screening, termination

 

🏛

CERT Insider Threat Center Carnegie Mellon SEI — 20+ years of insider threat indicators and pattern research

 

🛡

CISA Guidance Cybersecurity and Infrastructure Security Agency insider threat mitigation resources

 

 

 

Deliverables

## What Your Organization Receives

 

#### Domain-by-Domain Scored Report

Each of the five domains scored against the maturity scale with specific findings, evidence, and severity ratings. No boilerplate — every finding is tied to your organizational context.

 

#### Gap Prioritization Matrix

Ranked list of deficiencies sorted by risk impact and remediation effort. Distinguishes quick wins from structural changes that require budget and leadership sponsorship.

 

#### 90-Day Remediation Roadmap

Phased action plan with assigned ownership, milestones, and resource requirements. Designed to be presented directly to agency heads, boards, or executive committees without further translation.

 

#### Executive Summary

Two-page board-ready brief summarizing maturity posture, highest-risk gaps, and recommended investment priorities. Written for non-technical decision-makers.

 

 

 

Engagement

## How the Assessment Works

Standard engagement: 10–15 business days. All interviews and reviews can be conducted remotely or on-site.

 

Week 1

#### Scoping &amp; Document Review

NDA execution. Collection of existing policies, procedures, org charts, and prior audit reports. Initial stakeholder identification.

 

Week 2

#### Interviews &amp; Technical Review

Structured interviews with security, HR, legal, IT, and counterintelligence stakeholders. Technical controls validation. DLP and access governance testing.

 

Week 3

#### Tabletop &amp; Deception Testing

Adversarial tabletop exercise simulating insider threat scenarios. Deception environment assessment. Behavioral indicator validation.

 

Week 4

#### Report &amp; Roadmap Delivery

Scored report, gap matrix, 90-day roadmap, and executive summary delivered. Briefing to leadership. Optional: program build engagement begins.

 

 

 

Common Questions

## Frequently Asked Questions

 

  What does the Insider Threat CMM assess? The model evaluates five domains: detection and reporting mechanisms, behavioral analysis integration, data access and monitoring controls, program governance and leadership, and cross-functional coordination. Each domain is scored against a five-level maturity scale from Initial through Optimizing.

   What standards is the Insider Threat CMM grounded in? The framework aligns with National Insider Threat Task Force (NITTF) guidance, Executive Order 13587, Intelligence Community Directive 732, NIST SP 800-53 personnel security controls, and the CERT Division's insider threat indicators research at Carnegie Mellon University.

   Who is the assessment designed for? CISOs, insider threat program managers, counterintelligence officers, HR security directors, and compliance leads. The assessment has been deployed in government agencies, defense contractors, financial institutions, energy companies, and critical infrastructure operators.

   How long does the assessment take? A standard engagement runs 10 to 15 business days depending on organizational size. The process includes stakeholder interviews, policy review, technical controls evaluation, tabletop exercises, and delivery of the scored report with the 90-day remediation roadmap.

   How is this different from a compliance audit? A compliance audit confirms whether controls exist on paper. The CMM tests whether those controls actually work under operational conditions. The assessment includes adversarial tabletop exercises, behavioral indicator validation, and deception environment testing — capabilities that a standard compliance audit does not measure.

   Can the CMM be combined with other Treadstone 71 services? Yes. The Insider Threat CMM is frequently paired with the Cyber Intelligence Capability Maturity Model for a comprehensive dual assessment, or with the Intelligence Program Build service to implement remediation recommendations directly. The Fractional Intelligence Officer service can provide ongoing oversight after the initial assessment.

  

 

Contact

## Request a Confidential Briefing

Discuss your organization's insider threat posture with a Treadstone 71 intelligence professional. All initial consultations are conducted under NDA.

Office: [424.234.3629](tel:+14242343629)

<!-- AI:SCHEMA: Schema.org description of canonical page in JSON-LD format -->
<!-- AI:SCHEMA:BEGIN format=jsonld scope=page -->

```json
{
    "@context": "http:\/\/schema.org",
    "@graph": [
        {
            "@type": "Article",
            "author": {
                "@id": "https:\/\/www.treadstone71.com\/#superuserii_4b524ec0b2"
            },
            "dateModified": "2026-05-13T19:47:43Z",
            "datePublished": "2025-05-19T19:00:10Z",
            "description": "Insider Threat Capability Maturity Model — assess insider threat detection from ad-hoc through optimized. Roadmap to AI-augmented operations.",
            "headline": "Insider Threat Capability Maturity Model - CMM | Treadstone 71",
            "image": {
                "@type": "ImageObject",
                "url": "https:\/\/www.treadstone71.com\/images\/t71cyberrecon.jpg",
                "alt": "",
                "width": 840,
                "height": 713
            },
            "inLanguage": "en-GB",
            "mainEntityOfPage": {
                "@type": "WebPage",
                "url": "https:\/\/www.treadstone71.com\/services\/treadstone-71s-insider-threat-cmm"
            },
            "publisher": {
                "@id": "https:\/\/www.treadstone71.com\/#defaultPublisher"
            },
            "url": "https:\/\/www.treadstone71.com\/services\/treadstone-71s-insider-threat-cmm"
        },
        {
            "@type": "Person",
            "name": "SuperUserII",
            "@id": "https:\/\/www.treadstone71.com\/#superuserii_4b524ec0b2"
        },
        {
            "@id": "https:\/\/www.treadstone71.com\/#defaultPublisher",
            "@type": "Organization",
            "url": "https:\/\/www.treadstone71.com\/",
            "logo": {
                "@id": "https:\/\/www.treadstone71.com\/#defaultLogo"
            },
            "name": "Treadstone 71",
            "location": {
                "@id": "https:\/\/www.treadstone71.com\/#defaultPlace"
            }
        },
        {
            "@id": "https:\/\/www.treadstone71.com\/#defaultLogo",
            "@type": "ImageObject",
            "url": "https:\/\/www.treadstone71.com\/images\/DALL.E 2023-12-04 12.46.37 - A 3D circular logo for TREADSTONE 71 emphasizing themes of cyber operations deception management counterintelligence and cyber intelligence. The.png",
            "width": 1024,
            "height": 1024
        },
        {
            "@id": "https:\/\/www.treadstone71.com\/#defaultPlace",
            "@type": "Place",
            "address": {
                "@id": "https:\/\/www.treadstone71.com\/#defaultAddress"
            },
            "openingHoursSpecification": [
                {
                    "@type": "OpeningHoursSpecification",
                    "dayOfWeek": [
                        "monday",
                        "tuesday",
                        "wednesday",
                        "thursday",
                        "friday",
                        "saturday",
                        "sunday"
                    ],
                    "opens": "00:00",
                    "closes": "23:59"
                }
            ]
        },
        {
            "@id": "https:\/\/www.treadstone71.com\/#defaultAddress",
            "@type": "PostalAddress",
            "addressLocality": "",
            "addressRegion": "",
            "postalCode": "",
            "streetAddress": "",
            "addressCountry": "US"
        }
    ]
}
```

<!-- AI:SCHEMA:END -->

